curl --request POST \
--url https://api.example.com/api/auth/claim-links \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"api_key": "<string>",
"ttl_seconds": 123
}
'import requests
url = "https://api.example.com/api/auth/claim-links"
payload = {
"api_key": "<string>",
"ttl_seconds": 123
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({api_key: '<string>', ttl_seconds: 123})
};
fetch('https://api.example.com/api/auth/claim-links', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/auth/claim-links",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'api_key' => '<string>',
'ttl_seconds' => 123
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/auth/claim-links"
payload := strings.NewReader("{\n \"api_key\": \"<string>\",\n \"ttl_seconds\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/api/auth/claim-links")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"api_key\": \"<string>\",\n \"ttl_seconds\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/auth/claim-links")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"api_key\": \"<string>\",\n \"ttl_seconds\": 123\n}"
response = http.request(request)
puts response.read_body{
"data": {
"claim_path": "<string>",
"expires_at": "<string>",
"token": "<string>"
}
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"code": "<string>"
}Create a one-time claim link for an API key
Mint a one-time claim link that carries api_key to another device (the QR
onboarding leg). The submitted key is resolved through the gate’s own verifier chain
and the caller must own it (or be admin) per the module’s ownership rule; the response
returns the claim token ONCE plus a fragment-carrier path (/login#claim=<token>)
and an expiry.
Accepted oracle (deliberate, not an oversight): an unresolvable key answers 400 and a
valid-but-not-yours key answers 403, so an authenticated caller can tell a live key
from garbage. This adds NO capability the /api/auth/me carve-out does not already
grant a caller holding a candidate key. The uniform-404 no-oracle rule governs the
unauthenticated EXCHANGE surface, never this authed creation.
curl --request POST \
--url https://api.example.com/api/auth/claim-links \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"api_key": "<string>",
"ttl_seconds": 123
}
'import requests
url = "https://api.example.com/api/auth/claim-links"
payload = {
"api_key": "<string>",
"ttl_seconds": 123
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({api_key: '<string>', ttl_seconds: 123})
};
fetch('https://api.example.com/api/auth/claim-links', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/auth/claim-links",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'api_key' => '<string>',
'ttl_seconds' => 123
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/auth/claim-links"
payload := strings.NewReader("{\n \"api_key\": \"<string>\",\n \"ttl_seconds\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/api/auth/claim-links")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"api_key\": \"<string>\",\n \"ttl_seconds\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/auth/claim-links")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"api_key\": \"<string>\",\n \"ttl_seconds\": 123\n}"
response = http.request(request)
puts response.read_body{
"data": {
"claim_path": "<string>",
"expires_at": "<string>",
"token": "<string>"
}
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"code": "<string>"
}Authorizations
Body
Response
Success.
A one-time claim link. token is the claim secret surfaced ONCE (it rides the
claim_path URL fragment and is never stored in plaintext); expires_at is its
ISO-8601 expiry.
Show child attributes
Show child attributes

